All articles

Cloud & Productivity

Seven Microsoft 365 Security Settings Most Teams Miss

Microsoft 365 ships with sensible defaults for convenience, not for security. These are the tenant settings we change on day one.

Alpiba IT Team June 9, 2026 5 min read
Network operations engineer configuring cloud infrastructure

Defaults optimise for adoption

Microsoft configures a new tenant so that everything works immediately for everyone. That is the right call for onboarding and the wrong call for a business holding client financial or health data.

The following changes take an afternoon and remove a large share of the attack surface we see exploited in real incidents.

The settings we change first

  • Block legacy authentication protocols that bypass MFA entirely.
  • Enforce conditional access by device compliance and location risk.
  • Disable automatic external mail forwarding at the tenant level.
  • Restrict who can consent to third-party OAuth applications.
  • Turn on unified audit logging and retain it long enough to investigate.
  • Apply Safe Links and Safe Attachments to every mailbox, not a pilot group.
  • Review and time-limit global administrator accounts; use separate admin identities.

Then verify, quarterly

Tenant configuration drifts. New services get enabled, contractors get exceptions, and a policy that was correct in January is full of holes by June. Put a recurring configuration review on the calendar and treat the output as a report to leadership, not a technician's note.

Ready when you are

Need a Free Assessment?

In 30 minutes we'll map your risks, quick wins, and a right-sized IT roadmap — no obligation, no sales pressure.